File name:

3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446

Full analysis: https://app.any.run/tasks/b16bcca2-6bf3-4fb8-a72b-8c84babb9c66
Verdict: Malicious activity
Analysis date: April 28, 2024, 20:02:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

5673C04D81969A6603184069B6846213

SHA1:

49FDD9C69F1C281D94486029DFAA5108DFC168BF

SHA256:

3A6E2DE5B3DE6E67229B11F6D74A4F9AF70CCEC85C2573A905DF5A1F84A35446

SSDEEP:

24576:rq5TfcdHj4fmb9Ve9u2qTPIMeYyBMLlQjzCEzKJ9TtLzCwn1jAh0zQJ9TtDRli:rUTsamC9uxKjY5x1jAF5i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
    • Reads security settings of Internet Explorer

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
    • Reads the Internet Settings

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
      • dmr_72.exe (PID: 2104)
    • Device Retrieving External IP Address Detected

      • dmr_72.exe (PID: 2104)
  • INFO

    • Reads mouse settings

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
    • Checks supported languages

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
      • dmr_72.exe (PID: 2104)
      • wmpnscfg.exe (PID: 1872)
    • Checks Windows language

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
    • Reads the computer name

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
      • dmr_72.exe (PID: 2104)
      • wmpnscfg.exe (PID: 1872)
    • Create files in a temporary directory

      • 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe (PID: 4080)
    • Reads Environment values

      • dmr_72.exe (PID: 2104)
    • Reads the machine GUID from the registry

      • dmr_72.exe (PID: 2104)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (30.7)
.exe | UPX compressed Win32 Executable (30.1)
.exe | Win32 EXE Yoda's Crypter (29.5)
.exe | Win32 Executable (generic) (5)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:27 08:23:25+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 344064
InitializedDataSize: 1130496
UninitializedDataSize: 1654784
EntryPoint: 0x1e8900
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.1.6.4
ProductVersionNumber: 1.1.6.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
FileVersion: 1.1.6.4
Comments: CHIP Secured Installer
FileDescription: CHIP Secured Installer
ProductVersion: 1.1.6.4
LegalCopyright: Copyright © 2016 Chip Digital GmbH
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe dmr_72.exe wmpnscfg.exe no specs 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1872"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2104"C:\Users\admin\AppData\Local\Temp\DMR\dmr_72.exe" -install -54417509 -chipderedesign -a80c61fa351a416282afb39d6c109d6c - -BLUB2 -yrtmyirrbzvqebqz -4080C:\Users\admin\AppData\Local\Temp\DMR\dmr_72.exe
3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe
User:
admin
Company:
Chip Digital GmbH
Integrity Level:
HIGH
Description:
CHIP Secured Installer
Version:
1.1.6.4
Modules
Images
c:\users\admin\appdata\local\temp\dmr\dmr_72.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3968"C:\Users\admin\AppData\Local\Temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe" C:\Users\admin\AppData\Local\Temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CHIP Secured Installer
Exit code:
3221226540
Version:
1.1.6.4
Modules
Images
c:\users\admin\appdata\local\temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe
c:\windows\system32\ntdll.dll
4080"C:\Users\admin\AppData\Local\Temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe" C:\Users\admin\AppData\Local\Temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
CHIP Secured Installer
Exit code:
0
Version:
1.1.6.4
Modules
Images
c:\users\admin\appdata\local\temp\3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
3 481
Read events
3 458
Write events
23
Delete events
0

Modification events

(PID) Process:(4080) 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4080) 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4080) 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4080) 3a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2104) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:CID
Value:
dd8af842-f465-424d-9cf0-1f6a3367e342
(PID) Process:(2104) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:PID
Value:
chipderedesign
(PID) Process:(2104) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:lastPID
Value:
chipderedesign
(PID) Process:(2104) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2104) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2104) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
40803a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeC:\Users\admin\AppData\Local\Temp\DMR\dmr_72.exeexecutable
MD5:DA9E9A98A7CF8DA14F9E3C9973328FB7
SHA256:C1116053BBAC19AB273DC120C2984C235D116CDCC9E3AC437951B55465FD7063
40803a6e2de5b3de6e67229b11f6d74a4f9af70ccec85c2573a905df5a1f84a35446.exeC:\Users\admin\AppData\Local\Temp\DMR\yrtmyirrbzvqebqz.dattext
MD5:C800879C1C73DBBB198FC42669646AA7
SHA256:4C4DD62B579E43DC1C4CF859299DF3023409492281F173BC5C3D2CC00BB782D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
2
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
dmr_72.exe
GET
200
116.203.169.158:80
http://api.chip-secured-download.de/geoip/geoip.php?ip=38392e31322e3137302e323037&givezip=true
unknown
unknown
2104
dmr_72.exe
GET
200
116.203.169.158:80
http://api.chip-secured-download.de/dotnet/com
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2104
dmr_72.exe
116.203.169.158:80
api.chip-secured-download.de
Hetzner Online GmbH
DE
unknown
2104
dmr_72.exe
116.203.169.152:8080
ocs1.chdi-server.de
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
api.chip-secured-download.de
  • 116.203.169.158
malicious
ocs1.chdi-server.de
  • 116.203.169.152
unknown

Threats

PID
Process
Class
Message
2104
dmr_72.exe
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External IP Check (chip-secured)
No debug info